-
Hey there, Is there a process for downloading / updating the Wazuh Local Rule Set. I understand Wazuh Manager trys to connect to a github repo to download and update its hids / local ruleset. However we are running in an Airgapped Environment and I couldnt see anything in the SO Documentation. Cheers kl3ss |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 5 replies
-
I don't think Wazuh HIDS rules update anywhere near as frequently as NIDS rules, so this doesn't come up very often. If there is a rule or rules that you would like to add, you can add them to |
Beta Was this translation helpful? Give feedback.
-
Is there a process for downloading the updates from GitHub manually and manually pushing these out to the wazuh managers? |
Beta Was this translation helpful? Give feedback.
I don't think Wazuh HIDS rules update anywhere near as frequently as NIDS rules, so this doesn't come up very often. If there is a rule or rules that you would like to add, you can add them to
local_rules.xml
as shown here:https://docs.securityonion.net/en/2.3/wazuh.html#tuning-rules